Passing files by URL
The rules a file link must satisfy, and the content types each input accepts.
There is no upload endpoint. A file input takes a public HTTPS link, which we fetch, verify and copy into your Morphic project before the run starts. Your CDN stays the origin of your own content, and images, video, audio and documents all use one contract.
Every link must satisfy all of this
| Requirement | Detail |
|---|---|
| HTTPS | plain http is refused |
| It serves the file | the response body must be the bytes. A preview or share page — a Drive viewer, a Dropbox landing page, any HTML wrapper — is refused |
| A public host name | host names only. An IP address, localhost, or a name that resolves to a private address is refused |
| No credentials in the URL | https://user:pass@… is refused. A presigned query string is fine, and is never written to our logs |
| A listed content type | the response's Content-Type must be one of that input's url_content_types |
| Bytes that match | the file's first bytes are checked against the type it was served as, before it is kept. A PNG served as a PDF, an HTML page served as JSON, or any ZIP served as a DOCX is refused |
Inside max_bytes | checked from Content-Length first, then enforced again while the bytes stream |
| At most 3 redirects | more than three hops is refused |
| Valid for the whole fetch | a link that expires mid-transfer fails the run |
| Not empty | a link that serves zero bytes is refused |
| Delivered promptly | a host that cannot deliver the whole file inside about 40 seconds is refused, and a run's links together get about 90 seconds |
A signed link with a short lifetime is the usual cause of a half-fetched file. Give it at least a few minutes of validity past the moment you start the run.
Content types by input type
The exact list for an input is in its url_content_types. These are the types each input type can be configured to accept.
| Input type | Content types |
|---|---|
image | image/png, image/jpeg, image/webp, image/gif, image/tiff, image/avif, image/heic |
video | video/mp4, video/webm, video/quicktime, video/mpeg, video/x-matroska |
audio | audio/mpeg, audio/wav, audio/aac, audio/ogg, audio/mp4, audio/webm |
document | application/pdf, text/plain, text/markdown, text/csv, application/json, and DOCX |
Anything not on an input's list is refused. There is no "any file" input type, and an extension is never trusted — what the bytes are is what counts.
Per-run caps
Links and bytes are capped per run across all file inputs together — see Errors & limits.